Hackers exploit 32 zero-days on opening day of Pwn2Own Ireland 2026

Samsung Galaxy S26 breached twice as researchers collect $388,500

By LineZotpaper
Published
Read Time2 min
On the first day of the Pwn2Own Ireland 2026 hacking competition, security researchers exploited 32 zero-day vulnerabilities and earned $388,500, breaking into Samsung's Galaxy S26 flagship twice and chaining exploits against smart home lighting, AI databases and a cloud-based AI coding agent.

The opening day of the Pwn2Own Ireland 2026 contest saw competitors target products across seven categories: mobile phones (Apple iPhone 17, Samsung Galaxy S26 and Google Pixel 10), printers, smart home devices, messaging apps, AI infrastructure, AI coding apps, and a new category covering wellness healthcare devices.

The day's highlight was Samsung's Galaxy S26 being hacked twice, by Interrupt Labs, Ikotas Labs, and Nguyen Thanh Dat of Viettel Cyber Security. The Zero Day Initiative noted that some of the bugs exploited in each challenge were already known to the vendor.

Vũ Chí Thành and Huỳnh Đức Tin of VinSOC topped the leaderboard, winning $40,000 after chaining seven zero-days to exploit a Philips Hue Bridge Pro smart lighting hub, plus a further $40,000 for a five-zero-day exploit chain targeting the Oracle Autonomous AI Database.

Researchers also demonstrated LiteLLM zero-days, hacked the Lexmark CX532adwe and Canon imageFORCE 1643F multifunction printers, took down the OpenAI Codex cloud-based AI coding agent with a single argument-injection bug, and exploited four vulnerabilities to compromise a Sonos Era 300 smart speaker for the second time.

White Noise Club (Mikhail Evdokimov, Polina Smirnova and Mate Zombor) targeted the Google Pixel 10 but could not get their exploit working within the allotted time.

§

Analysis

Why This Matters

  • The exploited zero-days cover everyday consumer hardware (phones, printers, smart speakers) plus rapidly growing AI developer tools, showing where real-world attack surface is expanding.
  • Every bug disclosed here feeds into vendor patches, which is the point of the contest: criminals are likely hunting for the same weaknesses.
  • The takedown of OpenAI Codex signals that AI coding agents are now a recognized, exploitable target class.

Background

Pwn2Own is a long-running hacking competition organised by the Zero Day Initiative, in which researchers earn cash bounties for finding zero-day vulnerabilities in major products. Vendors receive the details of each bug so they can develop fixes before the findings are made public. This year's event in Ireland added dedicated AI and healthcare device categories for the first time.

Key Perspectives

Security researchers: The contest rewards skilled exploit chaining with significant payouts and leaderboard recognition, and several teams banked large sums on day one. Vendors: Companies such as Samsung, Oracle and OpenAI receive early disclosure of serious flaws, letting them patch before the details circulate widely. Critics and sceptics: Some of the bugs used against the Galaxy S26 were already known to Samsung, which undercuts the novelty of certain wins and raises questions about how fresh the disclosed vulnerabilities really are.

What to Watch

  • Whether White Noise Club or others succeed against the Google Pixel 10 before the contest ends.
  • Total payouts across the full competition, including the new wellness healthcare device category.
  • Which vendors issue patches first, especially for the OpenAI Codex and Oracle Autonomous AI Database exploits.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.